Skip to content

Security Warning: CVE-2021-44228 flagged by Wiz #483

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
SomethingNew71 opened this issue May 16, 2025 · 0 comments
Open

Security Warning: CVE-2021-44228 flagged by Wiz #483

SomethingNew71 opened this issue May 16, 2025 · 0 comments

Comments

@SomethingNew71
Copy link

Hey!

I'm opening this issue because my security scanner (Wiz) flagged a potential vulnerability: GHSA-jfh8-c2jp-5v3q (Log4Shell) in a project that uses react-native-get-random-values.

This is breaking a number of our builds within the corporate finance sector. Is there any chance you can use a different library to accomplish this goal or remove this library?

Here's the context:

Package: react-native-get-random-values
Link to your package.json - https://github.com/coveo/coveo.analytics.js/blob/master/package.json#L28
Dependency tree: indirectly used through coveo.analytics

Scanner: Wiz

CVE: CVE-2021-44228

Additionally, I have opened a PR in the offending app, but I am not sure it's actually maintained anymore

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant